vBulletin 5.x¶à¸ö¸ßΣÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-10-11Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-17271£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-17132£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4
Îó²î¸ÅÊö
vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾ÅäºÏ¿ª·¢µÄÒ»¿î¿ªÔ´µÄÉÌÒµWebÂÛ̳³ÌÐò¡£¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬vBulletin ¹Ù·½Ðû²¼ÁËÒ»¸öÈ«ÐÂÇå¾²²¹¶¡£¬£¬£¬£¬£¬£¬¸Ã²¹¶¡ÐÞ¸´ÁËCVE±àºÅΪCVE-2019-17271µÄSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬ÒÔ¼°CVE±àºÅΪCVE-2019-17132µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£
CVE-2019-17271 SQL×¢ÈëÎó²î
SQL×¢ÈëÎó²îÊÇÁ½¸ö¡°read in-band and time-based¡±µÄSQL×¢ÈëÎÊÌ⣬£¬£¬£¬£¬£¬ËüÃDZ£´æÓÚÁ½¸ö×ÔÁ¦µÄ¶ËµãÉÏ£¬£¬£¬£¬£¬£¬ÔÊÐí¾ßÓÐÊÜÏÞÖÆÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿â¶ÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
£¨1£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼üת´ïµ½¡°ajax/api/hook/getHookList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬£¬£¬£¬ÔÚºǫ́¾ÙÐÐSQLÅÌÎÊ֮ǰûÓоÓÉ׼ȷÑéÖ¤Óë¹ýÂË¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µã£¬£¬£¬£¬£¬£¬Í¨¹ý¡°read in-band¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÓû§¾ßÓС°canadminproducts¡±»ò¡°canadminstyles¡±µÄÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬í§Òâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£¡£¡£¡£¡£
£¨2£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼üת´ïµ½¡°ajax/api/widget/getWidgetList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬£¬£¬£¬ÔÚºǫ́¾ÙÐÐSQLÅÌÎÊ֮ǰûÓоÓÉ׼ȷÑéÖ¤Óë¹ýÂË¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µã£¬£¬£¬£¬£¬£¬Í¨¹ý¡°time-based¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÓû§¾ßÓС±canusesitebuilder¡±µÄÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬í§Òâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£¡£¡£¡£¡£
CVE-2019-17132 Ô¶³Ì´úÂëÖ´ÐÐÎó²î
vBulletin forum´¦Öóͷ£Óû§¸üÐÂÍ·Ïñ(Óû§µÄСÎÒ˽¼Ò×ÊÁÏ¡¢Í¼±ê»òͼÐÎÌåÏÖ)ÇëÇóʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÊÇͨ¹ý¡°data[extension]¡±ºÍ¡°data[filedata]¡±²ÎÊýת´ïµ½¡±ajax/api/User/updateAvatar¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬£¬£¬£¬ÔÚÓÃÓÚ¸üÐÂÓû§µÄavatar֮ǰûÓлñµÃ׼ȷÑéÖ¤¡£¡£¡£¡£¡£¡£¡£Õâ¿ÉÒÔÓÃÀ´×¢ÈëºÍÖ´ÐÐí§ÒâµÄPHP´úÂë¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÖÎÀíÔ±ÆôÓá°ÉúÑÄÍ·ÏñΪÎļþ¡±Ñ¡Ïî(¸ÃÑ¡ÏîĬÈϱ»½ûÓÃ)¡£¡£¡£¡£¡£¡£¡£
ͨ¹ýÍøÂç¿Õ¼äËÑË÷ÒýÇæ¿ÉÒÔµÃÖª£¬£¬£¬£¬£¬£¬ÔÚÈ«Çò¹æÄ£ÄÚ£¬£¬£¬£¬£¬£¬¶Ô»¥ÁªÍø¿ª·ÅµÄvBulletinÍøÕ¾Óнü3Íò¸ö£¬£¬£¬£¬£¬£¬ÆäÖн϶àÍøÕ¾Îª¹ú¼Ê´óÐÍÆóÒµËùά»¤µÄ¹ú¼ÊÉçÇøÂÛ̳£¬£¬£¬£¬£¬£¬ÒÔÊǸÃÎó²îÓ°ÏìÃæ½Ï´ó¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
CVE-2019-17132
POC£ºhttps://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://packetstormsecurity.com/files/154758/vBulletin-5.5.4-SQL-Injection.html
https://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html